The Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) has confirmed that approximately 200 accounts were compromised in a cybersecurity incident affecting its Microsoft SharePoint servers. The breach, which was detected on July 28, involved the theft of login credentials for both user and technical accounts.
BIT's security specialists identified unusual activity on their SharePoint servers and, upon confirming an intrusion, promptly restricted internet access to the platform and addressed the exploited vulnerabilities. By July 31, it was determined that login credentials had been compromised, leading to an immediate password reset for all affected accounts.
The agency suspects the attackers leveraged vulnerabilities in Microsoft SharePoint that were publicly disclosed and patched in Microsoft's mid-July Patch Tuesday updates. While BIT has not specified which particular flaw was exploited, security analysts suggest the incident may have involved CVE-2026-56164, a SharePoint privilege escalation vulnerability, or CVE-2026-50522, a remote code execution flaw. The latter has been known to facilitate the theft of SharePoint machine keys, allowing attackers to maintain access even after servers are patched.
BIT is collaborating with the Federal Office for Cybersecurity (BACS) and Microsoft to investigate the incident. The agency stated that the affected SharePoint platform is not authorized to store confidential or highly sensitive personal data. As of now, there is no evidence indicating that data beyond the compromised login credentials was exfiltrated.
The attackers are described as previously unknown actors. No group has publicly claimed responsibility for the breach.
In compliance with Switzerland's Information Security Act, BIT reported the incident to BACS and the State Secretariat for Security Policy. Technical indicators related to the attack have also been shared with operators of essential infrastructure via the BACS platform.
Federal administration employees are able to continue accessing and sharing documents through alternative methods, according to BIT.






